PT-2016-5147 · Pidgin+2 · Pidgin+2

Yves Younan

·

Published

2016-06-23

·

Updated

2017-03-30

·

CVE-2016-2378

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pidgin (affected versions not specified)
Description A buffer overflow issue exists in the handling of the MXIT protocol. This can be triggered by specially crafted data sent via the server, potentially resulting in memory corruption. The vulnerability can be exploited by a malicious server or an unfiltered malicious user sending negative length values.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1727
CVE-2016-2378
DLA-542-1
DSA-3620-1
MGASA-2016-0236
USN-3031-1

Affected Products

Alt Linux
Pidgin
Ubuntu